Loading HuntDB...

CVE-2018-1284

UNKNOWN
Published 2018-04-05T13:00:00Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2018-1284. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_float/xpath_long/xpath_int/xpath_short) to expose the content of a file on the machine running HiveServer2 owned by HiveServer2 user (usually hive) if hive.server2.enable.doAs=false.

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

Affected Products

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

✓ GitHub Reviewed LOW

Exposure of Sensitive Information to an Unauthorized Actor in Apache hive

GHSA-rxmr-c9jm-7mm8

Advisory Details

In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_float/xpath_long/xpath_int/xpath_short) to expose the content of a file on the machine running HiveServer2 owned by HiveServer2 user (usually hive) if hive.server2.enable.doAs=false.

Affected Packages

Maven org.apache.hive:hive
ECOSYSTEM: ≥0.6.0 <2.3.3
Maven org.apache.hive:hive-exec
ECOSYSTEM: ≥0.6.0 <2.3.3
Maven org.apache.hive:hive-service
ECOSYSTEM: ≥0.6.0 <2.3.3

CVSS Scoring

CVSS Score

2.5

CVSS Vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Advisory provided by GitHub Security Advisory Database. Published: November 21, 2018, Modified: March 4, 2024

References

Published: 2018-04-05T13:00:00Z
Last Modified: 2024-09-16T18:38:28.397Z
Copied to clipboard!